CVE-2020-2731
Last modified
CVE-2020-2731 is a low-severity vulnerability rated 3.9/10 on the CVSS scale. Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Core RDBMS accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Core RDBMS. CVSS 3.0 Base Score 3.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L).
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Database Server | 12.1.0.2 |
| Oracle | Database Server | 12.2.0.1 |
| Oracle | Database Server | 18c |
| Oracle | Database Server | 19c |
References
- https://www.oracle.com/security-alerts/cpujan2020.htmlPatch, Vendor Advisory
- https://www.oracle.com/security-alerts/cpujan2020.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-2731?
How severe is CVE-2020-2731?
How do I fix CVE-2020-2731?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-27298Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1…6.5
- CVE-2020-27299The affected product is vulnerable to an out-of-bounds read,…9.1
- CVE-2020-2730Vulnerability in the Oracle Financial Services Revenue Manag…5.4
- CVE-2020-27301A stack buffer overflow in Realtek RTL8710 (and other Ameba-…8
- CVE-2020-27302A stack buffer overflow in Realtek RTL8710 (and other Ameba-…8
- CVE-2020-27304The CivetWeb web library does not validate uploaded filepath…9.8
- CVE-2020-2732A flaw was discovered in the way that the KVM hypervisor han…6.8
- CVE-2020-2733Vulnerability in the JD Edwards EnterpriseOne Tools product …9.8
- CVE-2020-27336An issue was discovered in Treck IPv6 before 6.0.1.68. Impro…5.3
- CVE-2020-27337An issue was discovered in Treck IPv6 before 6.0.1.68. Impro…7.3
- CVE-2020-27338An issue was discovered in Treck IPv6 before 6.0.1.68. Impro…7.1
- CVE-2020-27339In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers d…6.7
Are you affected by CVE-2020-2731?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
